Securing HTTP-based APIs
Page 4 of 8
3. Data in transit protection
API data should be protected in transit using TLS (Transport Layer Security). Refer to the NCSC guidance on recommended profiles to securely configure TLS. APIs that use outdated TLS protocols or weak cipher suites expose data in transit to potential interception and decryption by attackers. This makes APIs susceptible to adversary-in-the-middle (AiTM) attacks, where sensitive information such as credentials and personal data can be compromised.
If an API is being hosted for a small community (or it is a private API), then consider using a mutually authenticated protocol such as Mutual TLS (mTLS). This will provide two-way authentication, ensuring that both the client and server verify each other's identity before establishing a secure connection. If you do use mTLS you may need to build a private PKI for the client authentication portion of mTLS.